Главная
Study mode:
on
1
Introduction
2
Who are we
3
What is the GCP
4
Example
5
Different Platforms
6
AWS Metadata API
7
GCP Metadata API
8
GCP Resource Hierarchy
9
Service Accounts
10
Kubernetes Engine
11
Default Service Accounts
12
Metadata Protections
13
Demo
14
Managed Service Accounts
15
Copying a Role
16
Cloud Build
17
Credentials
18
Demonstration
19
Recap
20
StackDriver
21
Event Threat Detection
22
Network Monitoring
23
Recommendations
24
Repost
Description:
Explore the security implications of the Google Cloud Platform (GCP) Metadata API in this BSidesSF 2020 conference talk. Delve into the differences between AWS and GCP metadata APIs, understanding the additional protections and higher stakes involved in GCP. Learn about attack vectors and defense strategies for the GCP metadata API, as well as the potential risks it poses to organizations. Gain insights into GCP's resource hierarchy, service accounts, and Kubernetes Engine. Witness demonstrations of managed service accounts, role copying, and Cloud Build credentials. Discover recommendations for enhancing security, including the use of StackDriver, event threat detection, and network monitoring. Acquire valuable knowledge to better protect your GCP environment and mitigate potential vulnerabilities associated with the metadata API.

The GCP Metadata API - Security Considerations, Vulnerabilities, and Remediations

Security BSides San Francisco
Add to list